Order data processing (ADV) with hurdles
In Germany, Section 11 of the Federal Data Protection Act and Section 80 of the Tenth Book of the Social Security Act regulate 'commissioned data processing' or 'commissioned data processing (ADV)'. They provide the framework for the 'outsourcing' of data processing contracts to external third parties. Since 2009, the Federal Data Protection Act has referred to a ten-point rule that clarifies issues such as deletion, reporting obligations and control rights in a court of law.
Depending on the type of data collected, each client must first satisfy itself that the contractor is certified for the task in question and that it has also introduced and implemented a security concept. This information is usually provided in writing. Only after this confirmation may the client transmit personal data.
Under liability law, it is not primarily the service provider who is responsible for breaches, but still the client.